GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      16 advisories
        Filter by severity
        
      
      
    
                    
                      A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted ...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-48415
                      
                      was published
                      May 21, 2025 
                    
                  
                    
                      The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform ...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2010-1428
                      
                      was published
                      May 2, 2022 
                    
                  
                    
                      The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2010-0738
                      
                      was published
                      May 2, 2022 
                    
                  
                    
                      Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5823
                      
                      was published
                      Jun 26, 2025 
                    
                  
                    
                      Medtronic MyCareLink Patient Monitor, 24950 MyCareLink Monitor, all versions, and 24952...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-8868
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43003
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-26651
                      
                      was published
                      Apr 8, 2025 
                    
                  
                    
                      The lack of access restriction to a resource from unauthorized users makes MXsecurity software...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-4739
                      
                      was published
                      Oct 18, 2024 
                    
                  
                    
                      PDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-39495
                      
                      was published
                      May 3, 2024 
                    
                  
                    
                      PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-39505
                      
                      was published
                      May 3, 2024 
                    
                  
                    
                      IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-27261
                      
                      was published
                      Apr 12, 2024 
                    
                  
                    
                      A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-33921
                      
                      was published
                      Jun 13, 2023 
                    
                  
                    
                      In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-29880
                      
                      was published
                      Mar 21, 2024 
                    
                  
                    
                      A user authorized to perform database queries may trigger denial of service by issuing specially...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-20923
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-4386
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-8949
                      
                      was published
                      May 14, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API